Once executed, the Trojan creates the following files:
- C:\Documents and Settings\Administrator\Local Settings\Temp\4.xls
- %Windir%\Downloaded Program Files\ZipExt32.dll
- %System%\atmd.exe
- %UserProfile%\Recent\4.xls.lnk
- %UserProfile%\ApplicationData\Microsoft\Office\Recent\4.xls.LNK
- %System%\msmsgs.exe
- %Temp%\word.exe
The Trojan creates following registry entry, so that it runs every time Windows starts:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\"sysres" = "atmd.exe"
The Trojan then connects to the following URL:
- [http://]bsek5.ggsddup.com/cgi-bin/Fupq[REMOVED]
- www.airlady.com
The Trojan drops malicious files on to the compromised computer and exploits the Microsoft Excel Header Parsing Remote Code Execution Vulnerability (
BID 27305)
It may replace the original malicious .xls file with a clean version.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":